Email Security
Email security.
Done properly.
SPF, DKIM, DMARC pre-configured. Anti-spam, anti-phishing, malware scanning. TLS 1.3 between servers. Tuned filtering. Zero setup needed.
~96%
Spam blocked at edge
TLS 1.3
Transport encryption
Auto
SPF / DKIM / DMARC
Tuned
Spam rules
Defense layers
Six layers between
bad actors and your inbox.
01
IP reputation filtering
Inbound mail from IPs on Spamhaus, Barracuda, and Sender Policy Framework blocklists is rejected at SMTP connection level. Most spam is killed before it even enters our infrastructure.
~88%
spam blocked at this layer
02
SPF + DKIM verification
Every incoming message is checked against the sender domain's SPF record and DKIM signature. Fails are quarantined or rejected based on the domain's DMARC policy.
Auto
no setup needed
03
Anti-spam content scoring
Tuned Rspamd rules score every message on content, header patterns, and sending behavior. Combined with IP reputation for a composite spam score. Threshold adjustable per-mailbox.
Tuned
tuned filtering rules
04
Anti-phishing heuristics
Link analysis, typosquatting detection, and homoglyph detection on sender domains. Flags messages that impersonate known brands or use lookalike domains.
AI-assisted
phishing detection
05
Malware + attachment scanning
All attachments scanned with ClamAV + commercial AV before delivery. Archive files unpacked and scanned recursively. Macros in Office files flagged automatically.
Recursive
archive scanning
06
Outbound signing + DMARC reporting
Every message you send is DKIM-signed with your domain key. DMARC reports aggregated and surfaced in KPanel. 14-day automated DMARC ramp from p=none to p=reject.
14-day
automated DMARC ramp
All layers included on every plan
No separate “advanced security” tier. Solo plan customers get the same protection as Enterprise. False positive rate stays around 0.1%. Quarantine reviewable in webmail, false positives released in one click.
DMARC explained
What DMARC actually does.
What they actually do.
SPF
Sender Policy Framework
What it is
A DNS record listing which mail servers are allowed to send mail from your domain.
Analogy
Like a guest list. Mail servers check the list before delivering.
Effect
Blocks attackers from sending mail as you from random servers.
DKIM
DomainKeys Identified Mail
What it is
Cryptographic signature added to every outbound message, verifiable via DNS.
Analogy
Like a wax seal. Receiving servers check the seal hasn't been broken.
Effect
Proves the message wasn't modified in transit and came from you.
DMARC
Domain-based Message Authentication
What it is
Tells receiving servers what to do if SPF or DKIM checks fail (quarantine, reject, or monitor).
Analogy
"If the seal is broken, throw the letter away."
Effect
Stops attackers spoofing your domain in their phishing campaigns.
DMARC explained
14-day automatic ramp from monitor to reject
Most hosts set DMARC to "none" forever and call it done. We progress to reject mode over two weeks. Stops attackers cold without breaking legitimate mail from third-party tools.
Day 0–7
p=none
Receive reports, take no action. Day 1 to 7 here.
Day 8–13
p=quarantine
Suspected fails go to spam. Day 8 to 14.
Day 14+
p=reject
Fails are bounced. Day 14+. Full protection.
Common questions.
Everything email security customers ask us most.
Is SPF/DKIM/DMARC set up automatically?+
What is tuned filtering?+
Can I whitelist / blacklist senders?+
What happens if a legitimate message gets flagged?+
Does TLS encryption mean my emails are private?+
Do I get DMARC reports?+
Stop being spoofed.
Email that takes security seriously.
SPF, DKIM, DMARC, anti-spam, anti-phishing. All configured, all monitored, all from KPanel.